PHP Object Injection Vulnerability in FacturaScripts by NeoRazorX
CVE-2026-104905
6.1MEDIUM
What is CVE-2026-104905?
FacturaScripts versions prior to 2026.7 are vulnerable to a PHP object injection flaw located in the WidgetSelect::processFormData() function. This vulnerability allows authenticated attackers to exploit the unserialize() function on unfiltered raw POST data, especially for multiple-select fields. By submitting a specially crafted serialized XLSXWriter object, attackers can invoke its __destruct() method, leading to the deletion of arbitrary files such as config.php. This results in potential denial of service and may facilitate unauthorized hijacking of application installations.
Affected Version(s)
facturascripts 2025.7 < 2026.7
